CVE-2025-8283: Netavark: podman: netavark may resolve hostnames to unexpected hosts

Published Jul 28, 2025
·
Updated

A vulnerability was found in the netavark package, a network stack for containers used with Podman. Due to dns.podman search domain being removed, netavark may return external servers if a valid A/AAAA record is sent as a response. When creating a container with a given name, this name will be used as the hostname for the container itself, as the podman's search domain is not added anymore the container is using the host's resolv.conf, and the DNS resolver will try to look into the search domains contained on it. If one of the domains contain a name with the same hostname as the running container, the connection will forward to unexpected external servers.

Other sources

Netavark was recently changed, when being used with podman, to remove the dns.podman search domain in detriment of using the host's search domain in the container. This leads to a possible DNS resolve confusion in some scenarios where the container created using podman have the same hostname as an external service. This may lead to containers communicating to unexpected servers instead of the desired one.

Red Hat

Affected Software

7 affected componentsFixes available
Red Hat netavark
Red Hat Podman
rust/netavark<1.15.1
1.15.1
redhat OpenShift Container Platform=4.0
redhat Enterprise Linux=8.0
redhat Enterprise Linux=9.0
redhat Enterprise Linux=10.0

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade rust/netavark to a version that resolves this vulnerability.

    Fixed in 1.15.1

Event History

Jul 28, 2025
Data Sourced
via Red Hat·02:37 PM
DescriptionSeverityAffected Software
CVE Published
via MITRE·06:16 PM
Data Sourced
via MITRE·06:16 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·07:15 PM
DescriptionSeverityWeaknessAffected Software
Advisory Published
via GitHub·09:31 PM
Data Sourced
via GitHub·09:31 PM
DescriptionSeverityWeaknessAffected Software
Jul 5, 57630
Event
via FIRST·04:13 PM
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2025-8283?

CVE-2025-8283 is classified as a moderate severity vulnerability due to the potential for incorrect DNS resolution.

2

How do I fix CVE-2025-8283?

To address CVE-2025-8283, update the netavark package to the latest version where this issue has been resolved.

3

Which software is affected by CVE-2025-8283?

CVE-2025-8283 affects the netavark package used with Red Hat Podman for container networking.

4

What is the impact of CVE-2025-8283?

The impact of CVE-2025-8283 is that malicious external servers may be returned as legitimate responses when creating containers.

5

When was CVE-2025-8283 disclosed?

CVE-2025-8283 was disclosed as part of ongoing security assessments of the netavark package.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203